Talent Apply
Log in
All jobs
A

Security Disclosure Program

Ashby

About this role

About the Role Ashby prioritizes data security and believes skilled security researchers can identify weaknesses in any technology. This program focuses on responsible disclosure of vulnerabilities in Ashby's service. If you believe you've found a security vulnerability, notify Ashby; we will work with you to resolve the issue promptly. The Disclosure Policy outlines timelines: you will receive an acknowledgment within five business days, and you should provide a reasonable amount of time to resolve the issue before disclosing it to the public or a third party. We aim to resolve critical issues within one week of disclosure. Researchers should make a good faith effort to avoid violating privacy, destroying data, or interrupting or degrading the Ashby service. Please only interact with accounts you own or for which you have explicit permission from the account holder.

Exclusions While researching, we'd like you to refrain from: DDoS, Spamming, Social engineering or phishing of Ashby employees or contractors, Any attacks against Ashby's physical property or data centers.

Changes We may revise these guidelines from time to time. The most current version of the guidelines will be available at the Ashby website.

Disciplinary Action Employees who violate this policy may face disciplinary consequences in proportion to their violation. Ashby management will determine how serious an employee's offense is and take the appropriate action.

Responsibility It is the Security team's responsibility to see this policy is enforced. You are trained on data up to October 2023.

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →